Privacy notice
How BYOptimise collects, uses and protects personal data, and the rights you have over it under UK GDPR.
Last updated 20 August 2026
01Who we are
BYOptimise (“we”) provides hosted marketing analytics and marketing mix modelling at byoptimise.com. We are the data controller for the personal data described in this notice. You can reach us at connor@byoptimise.com.
02What we collect
If you join the mailing list: your email address, whether you opted in to the weekly report, and the date you subscribed.
If you create an account: your email address and a hashed password. We never store your password in readable form.
If you connect a data source: the advertising, analytics and commerce data you authorise us to read — for example campaign spend, impressions, conversions and revenue. This is primarily business data rather than personal data, but it may contain personal data depending on your setup.
Automatically: standard server logs from our hosting provider, including IP address and browser type, kept for security and troubleshooting.
We do not buy personal data, and we do not track you across other websites.
03Why we use it, and our lawful basis
To provide the service — running models on your connected data and showing you the results. Lawful basis: performance of a contract.
To send the launch email and weekly report — only where you asked us to. Lawful basis: consent, which you can withdraw at any time using the unsubscribe link in any email.
To keep the service secure and working — logging, error diagnosis and abuse prevention. Lawful basis: legitimate interests.
To meet legal and tax obligations — retaining billing records. Lawful basis: legal obligation.
04We do not train shared models on your data
Your marketing data is used to produce results for your workspace and nothing else. It is not pooled with other customers’ data, not used to train models offered to anyone else, and not sold or shared for advertising.
05Who processes data on our behalf
We use a small number of processors, each under contract and each with access limited to what their function requires:
Vercel — application hosting and server logs.
Supabase — database and authentication, hosted in the EU (London region).
As the product develops we expect to add a cloud data warehouse and modelling infrastructure, and a payment processor. We will update this notice before any new processor handles your data. Where a processor transfers data outside the UK or EEA, that transfer relies on an adequacy decision or standard contractual clauses.
06How long we keep it
Mailing list entries: until you unsubscribe, or until we tell you the list is being retired.
Account and workspace data: for as long as your account is open, and for 30 days after you close it so it can be restored if closure was a mistake. After that it is deleted.
Billing records: six years, as UK tax law requires.
Server logs: 30 days.
07Your rights
Under UK GDPR you have the right to:
access a copy of your personal data; correct it if it is wrong; have it deleted; restrict or object to how we use it; receive it in a portable format; and withdraw consent at any time where consent is the basis we rely on.
Email connor@byoptimise.com to exercise any of these and we will respond within one month. If you are not satisfied with our response you can complain to the Information Commissioner’s Office at ico.org.uk.
08Security
Data is encrypted in transit and at rest. Each workspace is isolated at the database level using row-level security, so one customer’s data cannot be read from another customer’s session. Access to production systems is limited to those who need it.
We do not currently hold a SOC 2 or ISO 27001 certification, and we will not claim otherwise. If you need a data processing agreement, email us and we will provide one.
09Changes to this notice
If we change how we handle personal data we will update this page and change the date above. Where a change is significant we will tell subscribers and account holders by email rather than relying on you to check.